Certified Ethical Hacker Social Engineering and Physical Security 1 — Questions and Answers
Question 1: What is spear phishing and how does it differ from regular phishing?
- Targeted phishing aimed at specific individuals using personalized information, versus mass generic emails (Correct answer)
- Using a fishing metaphor to describe hacking
- A type of network scanning technique
- Phishing that uses spear-like USB devices
Correct answer: Targeted phishing aimed at specific individuals using personalized information, versus mass generic emails
Spear phishing targets specific individuals or organizations with highly personalized messages using researched information (name, position, projects), making them much more convincing and dangerous than generic phishing campaigns.
Question 2: What is pretexting in social engineering?
- Creating a fabricated scenario to manipulate a victim into providing information or access (Correct answer)
- Writing pretext for a book about hacking
- Testing network pretexts before deployment
- Sending pre-formatted text messages
Correct answer: Creating a fabricated scenario to manipulate a victim into providing information or access
Pretexting involves creating a convincing fabricated scenario (impersonating IT support, a vendor, or authority figure) to build trust and manipulate the target into revealing sensitive information or granting access.
Question 3: What is tailgating (piggybacking) in physical security?
- Following an authorized person through a secured door without presenting credentials (Correct answer)
- Parking too close to a building
- Monitoring network traffic from behind a firewall
- Tracking someone's online activities
Correct answer: Following an authorized person through a secured door without presenting credentials
Tailgating is a physical social engineering technique where an unauthorized person follows closely behind an authorized individual through a secured entrance, bypassing access controls through social pressure or stealth.
Question 4: What is a watering hole attack?
- Compromising a website frequently visited by the target group to infect their systems (Correct answer)
- Poisoning a physical water supply
- Flooding a network with data packets
- Creating fake Wi-Fi hotspots near water features
Correct answer: Compromising a website frequently visited by the target group to infect their systems
A watering hole attack identifies websites commonly visited by the target organization's employees, compromises those websites with malware, and waits for targets to visit and become infected.
Question 5: What is shoulder surfing and how can it be prevented?
- Observing someone's screen or keyboard to steal credentials; prevented with privacy screens and awareness (Correct answer)
- Surfing the internet over someone's shoulder using their Wi-Fi
- A type of network packet sniffing
- A physical attack on server room equipment
Correct answer: Observing someone's screen or keyboard to steal credentials; prevented with privacy screens and awareness
Shoulder surfing involves visually observing someone entering passwords, PINs, or viewing sensitive information on their screen. Prevention includes privacy screen filters, awareness training, and using biometric authentication.
Question 6: What is vishing and how does it differ from phishing?
- Voice-based phishing using phone calls to extract information, versus email-based phishing (Correct answer)
- A visual form of phishing using images
- A type of phishing that uses virtual reality
- Video-based phishing using fake video calls
Correct answer: Voice-based phishing using phone calls to extract information, versus email-based phishing
Vishing (voice phishing) uses phone calls or voicemail to impersonate trusted entities (banks, tech support, government) and manipulate victims into revealing sensitive information, as opposed to email-based phishing.
What is spear phishing and how does it differ from regular phishing?